Impact
A flaw in the Authentication Engine component of Oracle Access Manager allows an unauthenticated attacker with network access via HTTP to obtain read access to a subset of the data managed by the system. The vulnerability does not compromise integrity or availability, but it results in a breach of confidentiality for the exposed information. The weakness lies in an improper authentication check, permitting data disclosure without credential verification.
Affected Systems
Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0, deployed as part of Oracle Fusion Middleware, are affected. The issue is limited to the Authentication Engine component and does not extend to other parts of the Access Manager suite.
Risk and Exploitability
The CVSS base score of 5.3 reflects a moderate confidentiality impact, and the EPSS score of less than 1% indicates that exploitation is unlikely in practice. The vulnerability is not listed in the CISA KEV catalog. The attack vector is a network‑based HTTP request from an unauthenticated client to the Access Manager endpoint.
OpenCVE Enrichment